Data sharing system, method and apparatus, computer device and storage medium

By setting up a first data sharing agent on the data provider side to interact with the blockchain and using asymmetric keys and target authentication service nodes, the problems of privacy leakage and high overhead in data sharing are solved, and secure data sharing and resource conservation are achieved.

WO2025200555A1PCT designated stage Publication Date: 2025-10-02INSPUR SUZHOU INTELLIGENT TECH CO LTD

Patent Information

Application Number
PCT/CN2024/136882
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-29
Filing Date
2024-12-04
Publication Date
2025-10-02

AI Technical Summary

Technical Problem

Existing data sharing methods have the risk of privacy leakage and data abuse, and the overhead of blockchain nodes is high.

Method used

By setting up a first data sharing agent at the data provider end, using asymmetric keys and target authentication service nodes to interact with the blockchain, only the digital identity document of the first data sharing agent and the mirror summary certificate of the object to be shared are stored in the blockchain, thus achieving data isolation, reducing the risk of shared data leakage and abuse, and saving blockchain node overhead.

Benefits of technology

Effectively protect the privacy and security of shared data, reduce the risk of data leakage and abuse, and save blockchain node resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024136882_02102025_PF_FP_ABST
    Figure CN2024136882_02102025_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of block chains. Disclosed are a data sharing system, method and apparatus, a computer device and a nonvolatile readable storage medium. The system comprises: a first data sharing agent, used for creating an asymmetric key, receiving an object to be shared sent by a data providing end, acquiring image digest declaration content of said object, and sending to a target authentication service node a public key in the asymmetric key, access interface information of the first data sharing agent and the image digest declaration content of said object; and the target authentication service node, used for generating a digital identity and a digital identity document of the first data sharing agent and an image digest credential of said object on the basis of the public key, the access interface information of the first data sharing agent and the image digest declaration content of said object, and storing the digital identity document of the first data sharing agent and the image digest credential of the said object to a block chain. The present application can effectively protect shared data, and save the overhead of block chain nodes.
Need to check novelty before this filing date? Find Prior Art

Description

Data sharing system, method, device, computer equipment and storage medium

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to the Chinese patent application filed with the China Patent Office on March 29, 2024, with application number 202410372794.8, and application name “Data Sharing System, Method, Device, Computer Equipment and Storage Medium”, all contents of which are incorporated by reference into this application. Technical Field

[0003] The embodiments of the present application relate to the field of blockchain technology, and specifically to a data sharing system, method, apparatus, computer equipment, and non-volatile readable storage medium. Background Art

[0004] Data sharing allows users on a computer network to read, analyze, and process other people's data through the network. It allows a private data resource belonging to a certain user to be used by multiple applications, users, or organizations.

[0005] Currently, data sharing is achieved by writing shared data into blockchain nodes. However, writing shared data into blockchain nodes means that the shared data is public to all participants or participating nodes, which poses the risk of privacy leakage and data abuse. Furthermore, writing all shared data into blockchain nodes increases the overhead of blockchain nodes. Summary of the Invention

[0006] In view of this, the present application provides a data sharing system, method, apparatus, computer equipment and non-volatile readable storage medium to solve the problems of privacy leakage and data abuse risks in existing data sharing methods, as well as the high overhead of blockchain nodes.

[0007] In a first aspect, the present application provides a data sharing system, the system comprising:

[0008] The first data sharing agent is configured to create an asymmetric key, receive an object to be shared from a data provider, obtain a mirror image summary declaration of the object to be shared, and send the public key in the asymmetric key, access interface information of the first data sharing agent, and the mirror image summary declaration of the object to be shared to a target authentication service node;

[0009] The target authentication service node is configured to generate a digital identity of the first data sharing agent, a digital identity document of the first data sharing agent, and a mirror digest credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration content of the object to be shared, send the digital identity of the first data sharing agent and the mirror digest credential of the object to be shared to the first data sharing agent, and store the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared in the blockchain;

[0010] The blockchain includes multiple blockchain nodes, which are used to store the mirror summary credentials of the object to be shared by the data provider and the digital identity document of the first data sharing agent, so that the data user can access the target shared object in the first data sharing agent based on the mirror summary credentials of the object to be shared and the digital identity document of the first data sharing agent.

[0011] The data sharing system provided in this embodiment provides a first data sharing agent at the data provider end. The first data sharing agent sends the public key of the asymmetric key, the first data sharing agent's access interface information, and the mirror digest declaration content of the object to be shared to the target authentication service node. The target authentication service node generates a digital identity document of the first data sharing agent and a mirror digest credential of the object to be shared based on this information, and stores the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared on the blockchain. By isolating the data provider end from the blockchain, the first data sharing agent interacts with the blockchain via the target authentication service node, and only needs to store the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared on the blockchain. This effectively protects shared data, reduces the risk of shared data leakage and abuse, and saves blockchain node overhead.

[0012] In an optional embodiment, the system includes:

[0013] The data user terminal is configured to filter the target image summary credential from the blockchain based on the data element requirement information, obtain the digital identity of the corresponding first data sharing agent from the target image summary credential, obtain the digital identity document of the first data sharing agent from the blockchain based on the digital identity of the first data sharing agent, obtain the access interface information and public key of the first data sharing agent from the digital identity document of the first data sharing agent, and send the target image summary credential, the access interface information and public key of the first data sharing agent to the second data sharing agent;

[0014] The second data sharing agent is configured to initiate a data query request to the first data sharing agent based on the target image digest credential, the access interface information and the public key of the first data sharing agent;

[0015] The first data sharing agent is further configured to respond to the data query request, execute a data query operation, obtain a target shared object, and send the target shared object to the second data sharing agent;

[0016] The second data sharing agent is configured to receive a target shared object and send the target shared object to a data user.

[0017] In the data sharing system provided by this embodiment, a data user obtains a target image digest credential on the blockchain, then obtains the access interface information and public key of a first data sharing agent based on the target image digest credential. A second data sharing agent then initiates a data query request to the first data sharing agent based on the target image digest credential, the access interface information, and the public key of the first data sharing agent, thereby obtaining the target shared object. The data user can obtain the target shared object but cannot directly access it, significantly reducing the risk of data misuse. All operations between the data user and the data provider are performed through their corresponding data sharing agents, ensuring the privacy and security of the shared data.

[0018] In an optional implementation manner, the data user is configured to:

[0019] Obtain status information of the image summary certificate on the blockchain, and filter the target image summary certificate from the blockchain based on the status information of the image summary certificate on the blockchain and the data element requirement information.

[0020] The data sharing system provided in this embodiment can effectively protect shared data, reduce the risk of shared data leakage and abuse, and save the overhead of blockchain nodes.

[0021] In an optional implementation manner, the data user is further configured to:

[0022] After receiving the target shared object, the data provider of the target shared object is incentivized through the incentive interface provided by the data sharing service smart contract pre-deployed on the blockchain.

[0023] The data sharing system provided in this embodiment implements incentives for data providers of data sharing through a data sharing service smart contract, which not only protects the rights and interests of data providers but also stimulates their enthusiasm.

[0024] In an optional embodiment, the first data sharing agent is connected to the blockchain node corresponding to the data provider, and the first data sharing agent is used to:

[0025] Obtain several privacy protection policies through the interface provided by the data privacy protection smart contract pre-deployed on the blockchain;

[0026] If any privacy protection policy meets the preset privacy protection requirements, the privacy protection policy is determined as the target privacy protection policy of the object to be shared;

[0027] If all privacy protection policies do not meet the preset privacy protection requirements, a new privacy protection policy that meets the preset privacy protection requirements is created on the blockchain through the interface provided by the data privacy protection smart contract pre-deployed on the blockchain, and the new privacy protection policy is used as the target privacy protection policy for the object to be shared;

[0028] The first data sharing agent is used to:

[0029] In response to the data query request, executing a data query operation to obtain a target shared object, performing privacy protection processing on the target shared object based on a target privacy protection policy corresponding to the target shared object, obtaining a to-be-used shared object, and sending the to-be-used shared object to a second data sharing agent;

[0030] The second data sharing agent is used to:

[0031] Receive the shared object to be used, and send the shared object to be used to the data user.

[0032] The data sharing system provided in this embodiment performs privacy protection processing on shared objects through data privacy protection smart contracts pre-deployed on the blockchain and preset privacy protection requirements, ensuring that shared data is shared in the pre-required manner, effectively protecting shared data and reducing the risk of shared data leakage and abuse.

[0033] In an optional implementation, the first data sharing agent is further configured to:

[0034] Put the object to be shared into the database mirror management queue, and put the mirror digest credential of the object to be shared into the mirror digest credential management queue;

[0035] The first data sharing agent includes a database mirror management module and a mirror summary credential management module;

[0036] A database mirroring management module is configured to manage a database mirroring management queue;

[0037] The image digest credential management module is configured to manage the image digest credential management queue.

[0038] The data sharing system provided in this embodiment can effectively protect shared data and reduce the risk of shared data leakage and abuse.

[0039] In an optional implementation, the first data sharing agent is configured to:

[0040] The loop time delay between the first data sharing agent and each service node in the distributed digital identity and verifiable credential service cluster is obtained, and the service node with the shortest loop time delay with the first data sharing agent is used as the target authentication service node.

[0041] The data sharing system provided in this embodiment provides digital identity services and verifiable credential services to both parties of data sharing through service nodes in a distributed digital identity and verifiable credential service cluster. It can support flexible data provider access interfaces and provide distributed credential services. Moreover, the credential can interact with third-party platforms in a trusted manner, support cross-platform data interaction, effectively protect shared data, and reduce the risk of shared data leakage and abuse.

[0042] In an optional implementation, the target authentication service node is configured to:

[0043] Generate a digital identity and a data identity document of the first data sharing agent based on the public key in the asymmetric key and the access interface information of the first data sharing agent;

[0044] The first data sharing agent is further used to:

[0045] Receive the digital identity of the first data sharing agent, use the digital identity of the first data sharing agent to obtain the image summary certificate template from the target authentication service node, fill in the image summary declaration content of the object to be shared according to the image summary certificate template, obtain the target image summary data, and send the target image summary data to the target authentication service node, so that the target authentication service node issues the image summary certificate of the object to be shared based on the target image summary data.

[0046] The data sharing system provided in this embodiment provides digital identity services and verifiable credential services to both parties of data sharing through service nodes in a distributed digital identity and verifiable credential service cluster, which can effectively protect shared data and reduce the risk of shared data leakage and abuse.

[0047] In an optional implementation, the target authentication service node is configured to:

[0048] The digital identity document of the first data sharing agent and the mirror summary certificate of the object to be shared are stored on the blockchain through the identity and certificate on-chain smart contract pre-deployed on the blockchain.

[0049] The data sharing system provided in this embodiment stores the digital identity document of the first data sharing agent and the mirror summary certificate of the object to be shared on the blockchain through the identity and certificate chain smart contract, which can effectively protect the shared data and reduce the risk of shared data leakage and abuse.

[0050] In an optional implementation, the first data sharing agent is further configured to:

[0051] In response to the update request of the object to be shared from the data provider, the received object to be shared is updated accordingly.

[0052] The data sharing system provided in this embodiment, upon receiving an update request for an object to be shared from a data provider, will correspondingly update the received object to be shared, thereby ensuring the accuracy and consistency of the data.

[0053] In an optional implementation, the first data sharing agent is further configured to:

[0054] In response to the mirror digest credential status modification request from the data provider, the status of the mirror digest credential in the mirror digest credential management queue is modified accordingly.

[0055] The data sharing system provided in this embodiment ensures the accuracy and consistency of data by, upon receiving a request to modify the status of a mirror digest credential of a to-be-shared object from a data provider, causing the first data sharing agent to modify the status of the mirror digest credential in the mirror digest credential management queue accordingly.

[0056] In an optional embodiment, the blockchain is further used to:

[0057] In response to the mirror digest credential status modification request from the data provider, the status of the stored mirror digest credential is modified accordingly.

[0058] The data sharing system provided in this embodiment ensures the accuracy and consistency of data by making corresponding status modifications to the stored mirror digest credentials upon receiving a request to modify the status of the mirror digest credentials of the object to be shared from the data provider.

[0059] In an optional implementation, the first data sharing agent is further configured to:

[0060] Receive summary information of the object to be shared sent by the data provider;

[0061] Based on the summary information of the object to be shared, determine the image summary declaration content of the object to be shared.

[0062] In the data sharing system provided by this embodiment, the data provider sends summary information of the object to be shared to the first data sharing agent, and the first data sharing agent determines the mirror summary declaration content of the object to be shared based on the summary information of the object to be shared, which can effectively protect the data to be shared.

[0063] In a second aspect, the present application provides a data sharing method, which is applied to a data provider, and the method includes:

[0064] Using the first data sharing agent to create an asymmetric key, receiving the object to be shared sent by the data provider, obtaining the mirror summary declaration content of the object to be shared, and sending the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror summary declaration content of the object to be shared to the target authentication service node, so that the target authentication service node generates the digital identity of the first data sharing agent, the digital identity document of the first data sharing agent, and the mirror summary credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror summary declaration content of the object to be shared, and sends the digital identity of the first data sharing agent and the mirror summary credential of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror summary credential of the object to be shared in the blockchain;

[0065] Among them, the blockchain includes multiple blockchain nodes, which store the mirror summary certificate of the object to be shared by the data provider and the digital identity document of the first data sharing agent, so that the data user can access the target shared object in the first data sharing agent based on the mirror summary certificate of the object to be shared and the digital identity document of the first data sharing agent.

[0066] In a third aspect, the present application provides a data sharing method, which is applied to a data user, and the method includes:

[0067] Filter the target image summary certificate from the blockchain based on the data element requirement information;

[0068] Obtaining a digital identity of a corresponding first data sharing agent from the target image digest credential;

[0069] Obtaining a digital identity document of the first data sharing agent from the blockchain based on the digital identity of the first data sharing agent;

[0070] Obtaining access interface information and a public key of the first data sharing agent from the digital identity document of the first data sharing agent; wherein the first data sharing agent is used to create an asymmetric key, receive the object to be shared sent by the data provider, obtain the mirror summary declaration content of the object to be shared, and send the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror summary declaration content of the object to be shared to the target authentication service node, so that the target authentication service node generates the digital identity of the first data sharing agent, the digital identity document of the first data sharing agent, and the mirror summary credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror summary declaration content of the object to be shared, and sends the digital identity of the first data sharing agent and the mirror summary credential of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror summary credential of the object to be shared in a blockchain, wherein the blockchain includes multiple blockchain nodes, and the blockchain nodes store the mirror summary credential of the object to be shared by the data provider and the digital identity document of the first data sharing agent;

[0071] Using the second data sharing agent to initiate a data query request to the first data sharing agent based on the target image digest credential, the access interface information and the public key of the first data sharing agent, so that the first data sharing agent responds to the data query request, performs a data query operation, obtains the target shared object, and sends the target shared object to the data user;

[0072] Receives the target shared object.

[0073] In a fourth aspect, the present application provides a data sharing device, which is applied to a data provider, and includes:

[0074] a key creation module configured to create an asymmetric key using a first data sharing agent, receive an object to be shared from a data provider, obtain a mirror digest declaration of the object to be shared, and send the public key in the asymmetric key, access interface information of the first data sharing agent, and the mirror digest declaration of the object to be shared to a target authentication service node, so that the target authentication service node generates a digital identity of the first data sharing agent, a digital identity document of the first data sharing agent, and a mirror digest credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration of the object to be shared, sends the digital identity of the first data sharing agent and the mirror digest credential of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared in a blockchain;

[0075] Among them, the blockchain includes multiple blockchain nodes, which store the mirror summary certificate of the object to be shared by the data provider and the digital identity document of the first data sharing agent, so that the data user can access the target shared object in the first data sharing agent based on the mirror summary certificate of the object to be shared and the digital identity document of the first data sharing agent.

[0076] In a fifth aspect, the present application provides a data sharing device, which is applied to a data user terminal, and the device includes:

[0077] a target image summary credential screening module, configured to screen the target image summary credential from the blockchain based on the data element requirement information;

[0078] a digital identity acquisition module configured to acquire the digital identity of the corresponding first data sharing agent from the target image digest credential;

[0079] a digital identity document acquisition module, configured to acquire the digital identity document of the first data sharing agent from the blockchain based on the digital identity of the first data sharing agent;

[0080] The access interface information and public key acquisition module is configured to obtain the access interface information and public key of the first data sharing agent from the digital identity document of the first data sharing agent; wherein the first data sharing agent is used to create an asymmetric key, receive the object to be shared sent by the data provider, obtain the mirror summary declaration content of the object to be shared, and send the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror summary declaration content of the object to be shared to the target authentication service node, so that the target authentication service node generates the digital identity of the first data sharing agent, the digital identity document of the first data sharing agent, and the mirror summary credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror summary declaration content of the object to be shared, and sends the digital identity of the first data sharing agent and the mirror summary credential of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror summary credential of the object to be shared in a blockchain, wherein the blockchain includes multiple blockchain nodes, and the blockchain nodes store the mirror summary credential of the object to be shared by the data provider and the digital identity document of the first data sharing agent;

[0081] a target shared object acquisition module configured to use the second data sharing agent to initiate a data query request to the first data sharing agent based on the target image digest credential, the access interface information of the first data sharing agent, and the public key, so that the first data sharing agent responds to the data query request, performs a data query operation, obtains the target shared object, and sends the target shared object to the data user;

[0082] The target shared object receiving module is configured to receive the target shared object.

[0083] In a sixth aspect, the present application provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, computer instructions being stored in the memory, and the processor executing the data sharing method of the second aspect or the data sharing method of the third aspect by executing the computer instructions.

[0084] In the seventh aspect, the present application provides a computer non-volatile readable storage medium, on which computer instructions are stored, and the computer instructions are used to enable a computer to execute the data sharing method of the second aspect or the data sharing method of the third aspect.

[0085] In an eighth aspect, the present application provides a computer program product, comprising computer instructions, which are used to enable a computer to execute the data sharing method of the second aspect or the data sharing method of the third aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0086] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following briefly introduces the drawings required for use in the embodiments or related technical descriptions. Obviously, the drawings described below are some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0087] FIG1 is a schematic diagram of a data sharing system according to an embodiment of the present application;

[0088] FIG2 is a schematic diagram of another data sharing system according to an embodiment of the present application;

[0089] FIG3 is a flow chart of a data sharing method according to an embodiment of the present application;

[0090] FIG4 is a flow chart of another data sharing method according to an embodiment of the present application;

[0091] FIG5 is a flow chart of another data sharing method according to an embodiment of the present application;

[0092] FIG6 is a structural block diagram of a data sharing device according to an embodiment of the present application;

[0093] FIG7 is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present application. DETAILED DESCRIPTION

[0094] To make the purpose, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.

[0095] From the perspective of data ownership, data sharing can be divided into data providers and data users. In an information society, data is viewed as a resource and asset. Data sharing can create higher value for users, not only benefiting data providers but also unlocking value from their data. Data sharing can also break down data silos and improve analysis, thereby optimizing data-driven decision-making. From a societal perspective, data sharing can create new opportunities for collaboration and promote the development of the digital and sharing economies. For example, sharing health and medical data can significantly advance medical research.

[0096] Currently, data sharing methods include, but are not limited to, data file transfer, email, databases, data sharing cloud services, and blockchain. The following describes several data sharing methods.

[0097] Data file transfer: Data file transfer involves writing data into a file and transferring it between two systems or applications using a file transfer protocol (such as FTP (File Transfer Protocol), SCP (Special Containment Procedures, Secure Copy), HTTP (HyperText Transfer Protocol), or HTTPS (HyperText Transfer Protocol Secure)). This method can be end-to-end direct transmission, or the data provider can first upload the data file to an intermediary node, which then downloads the data file to the data consumer.

[0098] Email: Data providers can send data as attachments to the email addresses provided by data users via email. To improve transmission efficiency, data files are often compressed into a single package as an email attachment, which incurs compression overhead. If data is not compressed, the network transmission volume will be significantly greater than with compressed packages, resulting in greater transmission delays.

[0099] Databases: Applications can access data in remote databases through database access interfaces such as ODBC (Open Database Connectivity), JDBC (Java Database Connectivity), ADO.NET (ActiveX Data Objects for .NET), and PDO (PHP Data Objects). Through these interfaces, SQL (Structured Query Language) statements can be executed to query for matching data and even perform operations such as modifying, writing, and deleting data in the remote database. Distributed databases (such as HBase (Hadoop Database), Cassandra, and MongoDB) inherit the core features of traditional standalone databases, differing in that data is distributed across different database nodes. These nodes run on different machines, each supporting different operating systems. These nodes are managed by different database management systems, each with independent processing capabilities. They are connected via a network to form a global system, providing transparent operations such as querying, writing, and deleting records to users and applications.

[0100] Data sharing cloud service: This method is generally based on Internet-based file sharing or storage sharing. After the data provider uploads the data to the cloud, the data on the cloud can be accessed from any location through shared application services (such as Drop Box, Google Drive, MS One Drive). It can realize data cloud sharing within a team. For example, using MS One Drive, team members can store or share files on the cloud, and synchronize and back up data between different devices.

[0101] Blockchain approach: A blockchain is a distributed data storage system consisting of a set of nodes, each of which stores a copy of the ledger. Any write or modification to the ledger data is synchronized across all nodes, allowing transparent information sharing between nodes. A blockchain ledger is a linked list consisting of a series of blocks, each containing multiple transaction data. Blocks are linked in chronological order to form a chain. Each block header contains the hash of the previous block, so tampering with data in a previous block would break the hash checksum. Furthermore, modifying ledger data on a single node requires consensus. Only after network consensus is achieved will the corresponding data on all nodes be modified together and written into a new block at the end, allowing modification records to be traced.

[0102] Data file transfer or email requires transferring data files from the data provider to the data user, which incurs significant network transmission overhead. The data user may only need a small portion of the data. Furthermore, once shared, the data can be misused or distributed to unknown third parties, completely beyond the control of the data provider. Data ownership cannot be protected, posing significant data privacy and security risks.

[0103] While databases can provide the data needed for SQL querying, they carry significant data security risks. Once a malicious attacker obtains access keys, the data is completely exposed, potentially resulting in catastrophic consequences. Furthermore, the lack of incentives for data sharing significantly dampens the enthusiasm of data providers.

[0104] While cloud-based data sharing can provide efficient and convenient data sharing within teams, it's not suitable for cross-organizational or cross-authorization sharing scenarios. Furthermore, this sharing approach lacks incentives and fails to motivate data providers.

[0105] The blockchain approach can provide transparent data sharing among participating nodes. However, if all shared data is written to the ledger's blocks, it incurs significant on-chain storage overhead, as each node must store a copy. Furthermore, once shared data is on-chain, it becomes public to all participants or participating nodes, creating risks of privacy breaches and data misuse. Finally, simply sharing all data through the blockchain lacks an incentive mechanism for sharing.

[0106] It can be seen that in related technologies, data sharing mainly has the following two problems:

[0107] Privacy leakage: Every data provider has the legal and ethical obligation to protect the data privacy of its system customers. When sharing data, appropriate measures need to be taken to shield sensitive data to avoid leakage of customer privacy data.

[0108] Incentive mechanism: There is no incentive mechanism in data sharing, which cannot increase the enthusiasm of data providers.

[0109] In order to solve the above two problems, an embodiment of the present application provides a data sharing system, which isolates the data provider from the blockchain, and allows a first data sharing agent to interact with the blockchain via a target authentication service node. Only the digital identity document of the first data sharing agent and the mirror summary certificate of the object to be shared need to be stored in the blockchain. This can effectively protect shared data, reduce the risk of shared data leakage and abuse, and save the overhead of blockchain nodes.

[0110] According to an embodiment of the present application, a data sharing system embodiment is provided. FIG1 is a schematic diagram of a data sharing system according to an embodiment of the present application. As shown in FIG1 , the system includes:

[0111] The data provider 101 is configured to obtain the object to be shared from a database of the data provider, and send the object to be shared to a first data sharing agent.

[0112] Among them, the data provider selects a database instance as the object to be shared. Figure 2 is a schematic diagram of a data sharing system according to an embodiment of the present application. As shown in Figure 2, the data provider can send the object to be shared to the first data sharing agent through the data provider. As shown in Figure 1, the data sharing system may include multiple data providers (such as data provider A, data provider N). For any data provider, the data provider has a database belonging to it (such as database A, database N) and its corresponding first data sharing agent (such as first data sharing agent-A, first data sharing agent-N). Each data provider can send the object to be shared to the first data sharing agent through one data provider, or can send the object to be shared to the first data sharing agent through multiple data providers.

[0113] Data providers refer to various relevant entities that produce or collect data and provide data for sharing, such as hospitals that provide medical data.

[0114] A database is a warehouse used to organize, store, and manage data. It typically uses database software to provide services such as adding, deleting, modifying, and querying data. Examples of database software include MySQL, PostgreSQL, and MongoDB. A database can simultaneously create, manage, and maintain multiple database instances. Each database instance consists of one or more tables. A table structure consists of a set of data elements, or columns, and each table can contain multiple data records, or rows.

[0115] The object to be shared is a database instance to be shared in the database.

[0116] The first data sharing agent 102 is used to create an asymmetric key, receive the object to be shared sent by the data provider, obtain the mirror summary declaration content of the object to be shared, and send the public key in the asymmetric key, the access interface information of the first data sharing agent and the mirror summary declaration content of the object to be shared to the target authentication service node.

[0117] The first data sharing agent is deployed on the data provider end to provide a series of data sharing processing functions for the data provider end. It should be noted that each data provider end corresponds to a first data sharing agent.

[0118] Optionally, as shown in FIG2 , the first data sharing agent includes functions such as data sending and receiving, data desensitization, data encryption and decryption, data query, private key management, database mirror management, mirror summary credential management, and privacy policy control.

[0119] Among them, data transmission and reception: provides data sharing agents and DID&VC (Decentralized Identifier&Verifiable Credential, distributed digital identity and verifiable credentials) service nodes, the database system of the data provider and the blockchain nodes. Data transmission and reception, message parsing and other services.

[0120] Privacy policy control: Provides processing functions such as obtaining available or added privacy protection policies from blockchain nodes, or adding new privacy protection policies.

[0121] Data desensitization: also known as data privacy protection, is the shielding of sensitive information in the data, such as ID number, mobile phone number, card number, customer name, address, email address, etc. The shielding process can deform the data according to the desensitization rules. Among them, the desensitization rules can include deletion, conversion, replacement, encryption, etc., so as to prevent the leakage of sensitive data.

[0122] In this embodiment, data desensitization is to shield sensitive data in shared data according to the requirements of the privacy protection policy, such as deletion, replacement, encryption, etc.

[0123] Data encryption and decryption: The data provider uses asymmetric encryption technology to encrypt shared data based on the data user's public key, and the data user uses the private key to decrypt the encrypted shared data.

[0124] Asymmetric encryption involves each communicating party preparing a pair of public and private keys. The public key is publicly available and provided by the recipient to the sender. Typically, the public key is used to encrypt information, while the private key is retained by the creator (usually the recipient) and used to decrypt data encrypted with the public key.

[0125] In this embodiment, the first data sharing agent can create a pair of asymmetric keys or multiple pairs of asymmetric keys. It should be noted that the data provider determines which pair of asymmetric keys to use.

[0126] Private key management: When creating a DID (Decentralized Identity) identity, a pair of public and private keys is created. The public key is submitted to the service node in the DID&VC service cluster, and the private key is saved locally, allowing a data sharing agent to create multiple DID identities.

[0127] Data Query: Acting as a data sharing agent for data users, it provides interfaces and services for querying remote shared data. Additionally, acting as a data sharing agent for data providers, it executes query requests from remote data users and retrieves query results from a locally designated shared database.

[0128] Database mirroring management: Manage shared database instances, including adding a new shared database instance or deleting a shared database instance.

[0129] Mirror digest credential management: Manage the database mirror digest credential. You can create a new mirror digest credential or modify the mirror digest credential status. For example, you can modify the shared status of the mirror digest credential to normal, ended, abnormal, etc.

[0130] After the first data sharing agent 102 creates an asymmetric key for the object to be shared, it stores the private key locally and sends the public key, the access interface information of the first data sharing agent, and the image summary declaration of the object to be shared to the target authentication service node. The image summary declaration of the object to be shared includes the name of the database where the object to be shared resides, the data tables included in the object to be shared, and the structure and number of records in each data table.

[0131] It should be noted that the first data sharing agent interacts with a DID&VC service node through a RESTful API (Representational State Transfer API) that conforms to the REST (Representational State Transfer) architectural style. The interactions performed may include: registering a digital identity, creating a mirrored summary credential template, creating a mirrored summary credential, etc. The DID&VC service node is used to provide DID (Decentralized Identifier) ​​services and VC (Verifiable Credential) services.

[0132] DID services mainly provide entity DID registration, identity authentication, identity query and update services.

[0133] VC services mainly provide voucher template services and voucher services. Voucher template services include registration, update, and query services for voucher templates, while voucher services include voucher issuance and verification, as well as issuance and verification of verifiable expressions that support selective disclosure.

[0134] The target authentication service node 103 is used to generate the digital identity of the first data sharing agent, the digital identity document of the first data sharing agent and the mirror summary credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent and the mirror summary declaration content of the object to be shared, and send the digital identity of the first data sharing agent and the mirror summary credential of the object to be shared to the first data sharing agent, and store the digital identity document of the first data sharing agent and the mirror summary credential of the object to be shared in the blockchain.

[0135] The digital identity document of the first data sharing agent includes: a public key in an asymmetric key, access interface information of the first data sharing agent, and the digital identity of the first data sharing agent.

[0136] The image summary credential of the object to be shared includes: the name of the database where the object to be shared is located, the data tables included in the object to be shared, the structure and number of records of each data table, the digital identity of the first data sharing agent, etc.

[0137] The access interface information of the first data sharing agent may include: the access interface of the first data sharing agent and the access address of the first data sharing agent.

[0138] The access interface of the data sharing agent can be customized according to the needs. For example, (1) a service module for direct external data transmission can be implemented on the data sharing agent, such as based on a message publishing and subscription mechanism or a message queue mechanism. In this case, the access address and interface of the data sharing agent must be accessible to the external host. (2) A data transmission service module can also be implemented that is relayed by the connected blockchain node, such as the Advanced Messages Onchain Protocol (AMOP) provided by the open source alliance chain FISCO BCOS (Financial Industry Secure Blockchain Open Source Platform). This method does not require exposing the access address of the data sharing agent, but requires the connected blockchain node to support AMOP or a similar message mechanism.

[0139] Blockchain 104 includes multiple blockchain nodes, which are used to store the mirror digest credential of the object to be shared by the data provider and the digital identity document of the first data sharing agent, so that the data user can access the target shared object in the first data sharing agent based on the mirror digest credential of the object to be shared and the digital identity document of the first data sharing agent.

[0140] Blockchain is essentially a distributed data storage system characterized by decentralization, lack of third-party trust, open and transparent data, immutability, and traceability. Decentralization is reflected in the fact that a blockchain network consists of a distributed set of nodes, each with equal roles, without central or privileged nodes, and each node maintains a copy of the ledger. This lack of third-party trust stems from the fact that, unlike traditional information systems that rely on centralized authority for endorsement, blockchain relies on cryptographic algorithms and consensus mechanisms for endorsement, resulting in a high degree of trust in blockchain data. Data transparency is achieved because data on the blockchain is publicly available to all participants and can be queried through public interfaces, resulting in a high degree of data transparency. Immutability is achieved because once data is written, such as through interfaces defined by smart contracts, it is permanently stored and cannot be deleted or altered. Traceability is achieved because any write or modification of transaction data on the blockchain can be traced. Therefore, blockchain represents a novel application model for computer technologies such as distributed data storage, peer-to-peer transmission, consensus mechanisms, smart contracts, and encryption algorithms.

[0141] In this embodiment, a blockchain node is typically deployed on a data provider's network, serving as a participating node for that data provider and typically managed and maintained by that data provider. Currently, public blockchains face compliance issues in China, leading to the widespread adoption of consortium blockchain technology in the industry.

[0142] The following example illustrates the process of building a blockchain node network. In this example, the open-source consortium blockchain FISCO BCOS technology is used to build the blockchain node network, and the open-source component WeBASE (WeBank Blockchain Application Software Extension) serves as the blockchain data management component. First, the blockchain node network is installed and deployed using FISCO BCOS. The WeBASE component is then deployed. Next, the designed and implemented smart contract program is compiled and deployed using the visual interface provided by WeBASE. Finally, applications, such as the first or second data sharing agent in this example, can interact with the blockchain ledger through the smart contract call interface provided by WeBASE.

[0143] The data user can access the target shared object in the first data sharing agent through the data user terminal based on the mirror digest credential of the object to be shared and the digital identity document of the first data sharing agent.

[0144] Data users refer to various entities that obtain or use shared data through data sharing. Data providers and data users must comply with relevant national policies and requirements when carrying out data sharing, and provide or use shared data in a reasonable and legal manner. In the data sharing system of this embodiment, data providers can also be data users who use data shared by other entities.

[0145] Of course, in actual application scenarios, there are also pure data users, that is, users who do not provide shared data but only use other people's data. The data sharing agent of this pure data user is relatively simple, and its functions are a subset of those of the data provider, mainly including data transmission and reception, data encryption and decryption, data query, private key management, etc.

[0146] The data sharing system provided in this embodiment provides a first data sharing agent at the data provider end. The first data sharing agent sends the public key of the asymmetric key, the first data sharing agent's access interface information, and the mirror digest declaration content of the object to be shared to the target authentication service node. The target authentication service node generates a digital identity document of the first data sharing agent and a mirror digest credential of the object to be shared based on this information, and stores the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared on the blockchain. By isolating the data provider end from the blockchain, the first data sharing agent interacts with the blockchain via the target authentication service node, and only needs to store the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared on the blockchain. This effectively protects shared data, reduces the risk of shared data leakage and abuse, and saves blockchain node overhead.

[0147] Blockchain is used as a data sharing network. A blockchain node is created for each data provider, who is responsible for maintenance and management to ensure that data resources are under the control of the data provider.

[0148] The data sharing agent acts as the "gatekeeper" of the data provider. It can not only isolate the local database from the blockchain to better protect shared data resources, but also automatically provide query results to remote data users according to the rules defined by the privacy protection policy.

[0149] In some optional implementations, the data sharing system further includes:

[0150] The data usage end is used to screen the target image summary certificate from the blockchain based on the data element demand information, obtain the digital identity of the corresponding first data sharing agent from the target image summary certificate, obtain the digital identity document of the first data sharing agent from the blockchain based on the digital identity of the first data sharing agent, obtain the access interface information and public key of the first data sharing agent from the digital identity document of the first data sharing agent, and send the target image summary certificate, the access interface information and public key of the first data sharing agent to the second data sharing agent.

[0151] When a data user wants to obtain shared data, the data user selects the target image summary certificate from the blockchain based on the data element requirement information. The data element requirement information can be query fields related to the shared data to be obtained, etc.

[0152] The second data sharing agent is configured to initiate a data query request to the first data sharing agent based on the target image digest credential, the access interface information of the first data sharing agent, and the public key.

[0153] It should be noted that the second data sharing agent can also create a pair of asymmetric keys through asymmetric encryption technology, use the public key created by the first data sharing agent to encrypt the public key created by the second data sharing agent and the target image summary certificate, obtain data query data, and initiate a data query request to the first data sharing agent through the access interface information of the first data sharing agent, wherein the data query request includes data query data.

[0154] In an optional implementation, if the data provider supports SQL, the data query request can directly include a query SQL statement. If the data provider does not support SQL, a query interface and parameters can be defined.

[0155] The first data sharing agent 102 is further configured to respond to a data query request, execute a data query operation, obtain a target shared object, and send the target shared object to the second data sharing agent.

[0156] The first data sharing agent determines the target sharing object by obtaining the target image digest credential in the data query request, obtains the target sharing object from the database of the data provider, and sends the target sharing object to the second data sharing agent.

[0157] Optionally, the first data sharing agent decrypts the data query data using a private key stored locally to obtain the target image digest credential.

[0158] The second data sharing agent is configured to receive a target shared object and send the target shared object to a data user.

[0159] The data user receives the target shared object, and thus data sharing is completed.

[0160] In the data sharing system provided by this embodiment, a data user obtains a target image digest credential on the blockchain, then obtains the access interface information and public key of a first data sharing agent based on the target image digest credential. A second data sharing agent then initiates a data query request to the first data sharing agent based on the target image digest credential, the access interface information, and the public key of the first data sharing agent, thereby obtaining the target shared object. The data user can obtain the target shared object but cannot directly access it, significantly reducing the risk of data misuse. All operations between the data user and the data provider are performed through their corresponding data sharing agents, ensuring the privacy and security of the shared data.

[0161] Understandably, this data sharing approach differs from traditional distributed storage systems (such as distributed databases). While data users can use shared data, they cannot directly access it, significantly reducing the risk of data misuse. Furthermore, all operations between data users and data providers must be completed through the associated data sharing proxy. For example, when a data user queries remote shared data through the associated data sharing proxy, the provider's data sharing proxy will mask private data according to privacy protection policies before returning the query results.

[0162] In some optional implementations, the data user is configured to:

[0163] Obtain status information of the image summary certificate on the blockchain, and filter the target image summary certificate from the blockchain based on the status information of the image summary certificate on the blockchain and the data element requirement information.

[0164] The status information of the image summary credential can be normal, ended, abnormal, etc. The status information of the image summary credential obtained on the blockchain is a normal image summary credential, that is, the image summary credential available on the blockchain is obtained, and the target image summary credential is screened from the image summary credential available on the blockchain based on the data element requirement information. The target image summary credential is the image summary credential that meets the data element requirement among the image summary credential available on the blockchain.

[0165] The first data sharing agent connects to a blockchain node, known as an access node, and interacts with the access node through an interface provided by a set of pre-designed, implemented, and deployed smart contracts. These smart contracts include a data sharing service smart contract and a data privacy protection smart contract. The pre-deployed smart contracts are deployed in a manner specified by the data provider, enabling the shared objects to be shared in the manner specified by the data provider, effectively protecting private data.

[0166] The data sharing system provided in this embodiment implements privacy protection policy management based on smart contracts.

[0167] The operation of the data user end obtaining the available mirror digest certificate from the blockchain can be completed through the interface provided by the first data sharing agent based on the data sharing service smart contract pre-deployed on the blockchain.

[0168] Among them, the data sharing service smart contract includes the following interfaces:

[0169] CreateAccount account creation interface: The data provider calls this interface through the corresponding first data sharing agent to create a revenue account. The parameters include the digital identity of the first data sharing agent, and the revenue value is initialized to 0.

[0170] GetAvailableImage image summary certificate acquisition interface: obtains the image summary certificate on the chain and reads the image summary information from the declaration content of the image summary certificate. The parameter can be empty.

[0171] Inspire Incentive API: This API incentivizes a data provider. Parameters include the DID corresponding to the image summary credential. Each image summary credential uses a unique DID as its identifier. The smart contract program adds an incentive value to the corresponding data provider's revenue account. For example, the incentive value can be defined as a variable and passed in via a smart contract interface parameter.

[0172] In some optional implementations, the data user is further configured to:

[0173] After receiving the target shared object, the data provider of the target shared object is incentivized through the incentive interface provided by the data sharing service smart contract pre-deployed on the blockchain.

[0174] It is understood that the data user can determine whether to incentivize the data provider of the target shared object based on the needs of the data user. If incentivization is required, the incentive interface provided by the data sharing service smart contract pre-deployed on the blockchain is called to incentivize the data provider of the target shared object.

[0175] The data sharing system provided in this embodiment implements incentives for data providers of data sharing through a data sharing service smart contract, which not only protects the rights and interests of data providers but also stimulates their enthusiasm.

[0176] In some optional implementations, the first data sharing agent is connected to the blockchain node corresponding to the data provider, and the first data sharing agent 102 is configured to:

[0177] Several privacy protection strategies are obtained through the interface provided by the data privacy protection smart contract pre-deployed on the blockchain.

[0178] Optionally, the available privacy protection policy pre-added by the data provider is obtained through the interface provided by the data privacy protection smart contract pre-deployed on the blockchain.

[0179] If any privacy protection policy meets the preset privacy protection requirements, the privacy protection policy is determined as the target privacy protection policy of the object to be shared.

[0180] If all privacy protection strategies do not meet the preset privacy protection requirements, a new privacy protection strategy that meets the preset privacy protection requirements is created on the blockchain through the interface provided by the data privacy protection smart contract pre-deployed on the blockchain, and the new privacy protection strategy is used as the target privacy protection strategy for the object to be shared.

[0181] Among them, the preset privacy protection requirements are formulated by the data provider based on actual conditions.

[0182] The first data sharing agent 102 is configured to:

[0183] In response to the data query request, a data query operation is executed to obtain a target shared object, privacy protection processing is performed on the target shared object based on a target privacy protection policy corresponding to the target shared object, a to-be-used shared object is obtained, and the to-be-used shared object is sent to the second data sharing agent.

[0184] The second data sharing agent is used to:

[0185] Receive the shared object to be used, and send the shared object to be used to the data user.

[0186] The data provider sets a privacy protection policy for the shared object through the first data sharing agent. This privacy protection policy is managed and maintained by a data privacy protection smart contract. The first data sharing agent reads and writes the privacy protection policy on the blockchain through the interface defined by the data privacy protection smart contract. Smart contract programs must be designed and implemented in advance and deployed to the blockchain through the smart contract deployment interface. Different blockchain implementation technologies have different corresponding smart contract deployment operations. For example, on the open source consortium blockchain FISCO BCOS, the smart contract management function provided by the open source component WeBASE enables visual compilation and deployment of smart contracts. On another open source consortium blockchain, HyperLedger Fabric, chaincode (including smart contract programs) is compiled and deployed through command line scripts provided by the open source project.

[0187] Among them, the data privacy protection smart contract includes the following interfaces:

[0188] Init initialization interface: Initializes key parameters of the smart contract. You can define different strictness indicators for privacy protection. For example, you can define the following indicators:

[0189] Usable: Shared data can be used for analysis by data users, but may not be visible.

[0190] Visible to users: Data users can obtain shared data.

[0191] To be anonymized: Shared data needs to be anonymized before being sent to the user.

[0192] Encrypted transmission: Shared data needs to be encrypted before being sent to the user.

[0193] GetAvaiablePolicy obtains the policy interface: obtains the existing privacy protection policy (i.e., a combination of the above indicators).

[0194] AddPolicy adds a policy interface: adds a new privacy policy, including policy name, policy ID (IDentity, identity identification number), indicator combination and other information. Each privacy protection policy can be identified by policy name or policy ID.

[0195] The first data sharing agent obtains the existing privacy protection policy from the blockchain through the interface provided by the data privacy protection smart contract, adds a new privacy protection policy according to actual needs, and specifies a privacy protection policy for the object to be shared.

[0196] The first data sharing agent at the data provider end performs privacy protection processing on the target shared object according to the target privacy protection policy corresponding to the target shared object. For example, if the target privacy protection policy of the target shared object is "usable and invisible to the user", the target shared object will only provide the quantity that meets the conditions but cannot provide the specific data content. If the target privacy protection policy is "usable, visible to the user, desensitized, encrypted transmission", the target shared object must first be desensitized to remove sensitive data (such as name, address, contact number, etc.), and then the desensitized target shared object is encrypted based on the public key provided by the data user end to obtain the shared object to be used, and the shared object to be used is sent to the second data sharing agent.

[0197] It should be noted that the public key provided by the data user is the public key created by the data user through the second data sharing agent when performing data query. The second data sharing agent saves the private key created when performing data query locally. The public key can be obtained from the data query data or from the digital identity document of the second data sharing agent corresponding to the data user stored on the blockchain.

[0198] After receiving the shared object to be used, the second data sharing agent decrypts the shared object to be used using the private key stored locally, obtains the decrypted shared object to be used, and sends the decrypted shared object to be used to the data user.

[0199] In some optional implementations, the first data sharing agent 102 is further configured to:

[0200] The object to be shared is placed in the database mirror management queue, and the mirror digest credential of the object to be shared is placed in the mirror digest credential management queue.

[0201] The first data sharing agent includes a database mirroring management module and a mirroring digest credential management module.

[0202] The database mirroring management module is configured to manage the database mirroring management queue.

[0203] The image digest credential management module is configured to manage the image digest credential management queue.

[0204] In some optional implementations, the first data sharing agent 102 is configured to:

[0205] The loop time delay between the first data sharing agent and each service node in the distributed digital identity and verifiable credential service cluster is obtained, and the service node with the shortest loop time delay with the first data sharing agent is used as the target authentication service node.

[0206] With the development of the digital economy, more and more transactions rely on digital identities and digital credentials. Physical identities cannot meet the requirements of online use because digital copies of physical documents are easy to forge and their legitimacy is difficult to verify remotely. Traditional physical credentials and their electronic counterparts cannot effectively cope with the challenges of high-frequency requests, massive data, privacy and security, and the emergence of new digital scenarios. In order to address these challenges, distributed digital identity technology and verifiable credential technology have been proposed and developed rapidly. Standards related to distributed digital identity identification and verifiable credentials include: (1) Distributed digital identity DID, which is a globally unique digital identity identifier with distributed, resolvable and verifiable properties. The difference from traditional identifiers is that data is stored autonomously rather than centrally hosted, the identifier is self-generated, self-assigned, and self-managed rather than uniformly assigned, and the authenticity of the data is endorsed by an encryption algorithm rather than by an authoritative institution. (2) Verifiable credential VC, which is a descriptive statement issued by an authoritative entity to endorse certain attributes of another entity and is accompanied by its own digital signature; the VC specification defines the data format of verifiable credentials, forming a standard for cross-domain and cross-institutional data interaction.

[0207] The distributed digital identity and verifiable credential service cluster consists of a group of DID&VC service nodes (referred to as service nodes). Each service node is peer-to-peer. The first data sharing agent can access a designated service node, i.e., a service node configured by the user, or obtain a list of available service nodes, such as the available service node information registered in the blockchain. The first data sharing agent obtains the list of available service nodes through the blockchain node, and selects the best service node, i.e., the service node with the shortest round-trip time delay between the first data sharing agent and each service node in the list of available service nodes, based on the round-trip time delay (RTT) between the first data sharing agent and each service node in the list of available service nodes.

[0208] In some optional implementations, the target authentication service node 103 is configured to:

[0209] Generate a digital identity and a data identity document of the first data sharing agent based on the public key in the asymmetric key and the access interface information of the first data sharing agent;

[0210] The first data sharing agent is further used to:

[0211] Receive the digital identity of the first data sharing agent, use the digital identity of the first data sharing agent to obtain the image summary certificate template from the target authentication service node, fill in the image summary declaration content of the object to be shared according to the image summary certificate template, obtain the target image summary data, and send the target image summary data to the target authentication service node, so that the target authentication service node issues the image summary certificate of the object to be shared based on the target image summary data.

[0212] Each data sharing agent needs to register a digital identity, i.e., DID, with the DID&VC service node. When registering the DID, the data sharing agent must create a pair of asymmetric keys locally, save the private key locally, and provide the data sharing agent's access interface information and public key for registering the DID. This information will be written into the corresponding DID document (saved on the chain). After registering the DID, the data sharing agent can obtain the mirror summary certificate template from the service node, or create a new mirror summary certificate template as needed. Assuming that an existing template is used, the declaration content of the mirror summary certificate can be filled in according to the requirements of the existing template. Optionally, the declaration content of the mirror summary certificate may include: the name of the database where the object to be shared is located, which data tables the object to be shared includes, the structure and number of records of each data table, the digital identity of the first data sharing agent, the privacy protection policy ID, the sharing status, i.e., the status information of the mirror summary certificate, etc., and then submit an application to create the certificate.

[0213] The DID&VC service node issues a mirror summary certificate based on the application information for creating a certificate, and puts the mirror summary certificate on the chain. After the DID&VC service node receives the application for creating a certificate, the review user can complete the review and issuance of the mirror summary certificate declaration content as needed, or the program can automatically complete the check (such as checking the applicant's DID, which is the digital identity of the data sharing agent, the declaration content, the certificate template, etc.) and then directly issue the mirror summary certificate. Each mirror summary certificate uses a certificate DID as a unique identifier. The certificate issuance process can be customized according to needs. The certificate chain is completed through the certificate chain smart contract, which defines a set of operations related to writing and reading certificates on the chain. It will not be described in detail here. You can refer to the WeIdentity Evidence smart contract section of the open source WeIdentity project.

[0214] In some optional implementations, the target authentication service node 103 is configured to:

[0215] The digital identity document of the first data sharing agent and the mirror summary certificate of the object to be shared are stored on the blockchain through the identity and certificate on-chain smart contract pre-deployed on the blockchain.

[0216] In some optional implementations, the first data sharing agent 102 is further configured to:

[0217] In response to the update request of the object to be shared from the data provider, the received object to be shared is updated accordingly.

[0218] The update may be adding a new object to be shared or deleting a received object to be shared, etc. The update may be completed by adding a new object to be shared to the database mirror management queue or deleting an object to be shared in the database mirror management queue through the database mirror management module.

[0219] In some optional implementations, the first data sharing agent 102 is further configured to:

[0220] In response to the mirror digest credential status modification request from the data provider, the status of the mirror digest credential in the mirror digest credential management queue is modified accordingly.

[0221] Among them, the modification of the mirror digest credential status can be to create a new mirror digest credential or modify the status of the received mirror digest credential. For example, when the data provider no longer shares a certain object to be shared, the status of the mirror digest credential of the object to be shared is changed from normal status to end status.

[0222] Through the image digest credential management module, it is possible to create a new image digest credential to the image digest credential management queue, and it is also possible to modify the status of the image digest credential in the image digest credential management queue.

[0223] In some optional embodiments, blockchain 104 is further configured to:

[0224] In response to the mirror digest credential status modification request from the data provider, the status of the stored mirror digest credential is modified accordingly.

[0225] It is understandable that if the data provider modifies the status of the mirror digest certificate that has been uploaded to the chain, the blockchain will respond to the mirror digest certificate status modification request and make corresponding status modifications to the corresponding stored mirror digest certificate.

[0226] In some optional implementations, the first data sharing agent 102 is further configured to:

[0227] Receive summary information of the object to be shared sent by the data provider.

[0228] The image summary declaration content of the object to be shared is determined based on the summary information of the object to be shared.

[0229] Among them, the above-mentioned data provider will completely dump the data of the database instance to be shared or export the data into a data file, and send the data file to the first data sharing agent, which will create and import the corresponding database instance. That is, the first data sharing agent creates and saves a copy of the database instance to be shared.

[0230] It should be noted that the data provider can also send only the summary information of the object to be shared to the first data sharing agent, where the summary information of the object to be shared includes the database name of the database instance to be shared, which data tables are included, the structure and number of records of each data table, and database access interface information, etc., where the database access interface information includes the access interface method, host address, port number, user name and password, etc.

[0231] The data sharing system in this embodiment primarily implements the sharing of database-based data resources. To enable data sharing of other data types, such as documents, images, and videos, sharing modules for different data types can be implemented in the first data sharing agent. For example, taking document sharing as an example, a summary credential can be created for each shared document, and a keyword query for the document can be provided. The data user decides whether to obtain the full document based on the keyword query results. In addition, the data provider can formulate a privacy protection policy for the document (such as availability, user visibility, desensitization requirements, encrypted transmission, etc.).

[0232] According to an embodiment of the present application, an embodiment of a data sharing method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0233] In this embodiment, a data sharing method is provided, which can be used in the above-mentioned data providing end, such as a central processing unit, a server, etc. The data sharing method includes:

[0234] An asymmetric key is created using the first data sharing agent, an object to be shared sent by the data provider is received, a mirror summary declaration content of the object to be shared is obtained, and the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror summary declaration content of the object to be shared are sent to the target authentication service node, so that the target authentication service node generates the digital identity of the first data sharing agent, the digital identity document of the first data sharing agent, and the mirror summary certificate of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror summary declaration content of the object to be shared, and sends the digital identity of the first data sharing agent and the mirror summary certificate of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror summary certificate of the object to be shared in the blockchain.

[0235] Among them, the blockchain includes multiple blockchain nodes, which store the mirror summary certificate of the object to be shared by the data provider and the digital identity document of the first data sharing agent, so that the data user can access the target shared object in the first data sharing agent based on the mirror summary certificate of the object to be shared and the digital identity document of the first data sharing agent.

[0236] The data sharing method provided in this embodiment is the same as that described in the previous embodiment, and will not be repeated here. The data sharing method provided in this embodiment is also used to implement the above system embodiment and optional implementation methods, and will not be repeated here.

[0237] In this embodiment, a data sharing method is provided. FIG3 is a flow chart of the data sharing method according to an embodiment of the present application. As shown in FIG3 , the process of the data sharing method includes:

[0238] Step 1: The data provider selects a database instance as the object to be shared.

[0239] Step 2: Send the object to be shared to the local data sharing agent of the data provider, that is, the first data sharing agent.

[0240] Step 3: After the first data sharing agent receives the object to be shared, the data provider sets a privacy protection policy for it through the first data sharing agent.

[0241] Step 4: The first data sharing agent sends the image summary declaration content to the DID&VC service node and applies to create an image summary certificate.

[0242] Step 5: The DID&VC service node issues a mirror summary certificate based on the certificate application information and uploads the mirror summary certificate to the chain.

[0243] Step 6: The first data sharing agent puts the shared object into the database mirror management queue and puts the chained mirror summary certificate into the mirror summary certificate management queue.

[0244] The shared object is the object to be shared corresponding to the image summary certificate that has been uploaded to the chain.

[0245] The data sharing method provided in this embodiment is the same as that described in the previous embodiment, and will not be repeated here. The data sharing method provided in this embodiment is also used to implement the above system embodiment and optional implementation methods, and will not be repeated here.

[0246] In this embodiment, a data sharing method is provided, which can be used for the above-mentioned data user terminal, such as a central processing unit, a server, etc. FIG4 is a flow chart of the data sharing method according to an embodiment of the present application. As shown in FIG4 , the process includes the following steps:

[0247] Step S401: Filter the target image summary certificate from the blockchain based on the data element requirement information.

[0248] Step S402: Obtain the digital identity of the corresponding first data sharing agent from the target image digest credential.

[0249] Step S403: Obtain the digital identity document of the first data sharing agent from the blockchain based on the digital identity of the first data sharing agent.

[0250] Step S404: Acquire the access interface information and public key of the first data sharing agent from the digital identity document of the first data sharing agent.

[0251] Among them, the first data sharing agent is used to create an asymmetric key, receive the object to be shared sent by the data provider, obtain the mirror summary declaration content of the object to be shared, and send the public key in the asymmetric key, the access interface information of the first data sharing agent and the mirror summary declaration content of the object to be shared to the target authentication service node, so that the target authentication service node generates the digital identity of the first data sharing agent, the digital identity document of the first data sharing agent and the mirror summary certificate of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent and the mirror summary declaration content of the object to be shared, and sends the digital identity of the first data sharing agent and the mirror summary certificate of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror summary certificate of the object to be shared in the blockchain. The blockchain includes multiple blockchain nodes, and the blockchain nodes store the mirror summary certificate of the object to be shared by the data provider and the digital identity document of the first data sharing agent.

[0252] Step S405: Use the second data sharing agent to initiate a data query request to the first data sharing agent based on the target image summary certificate, the access interface information and public key of the first data sharing agent, so that the first data sharing agent responds to the data query request, performs a data query operation, obtains the target shared object, and sends the target shared object to the data user.

[0253] Step S406: receiving the target shared object.

[0254] The data sharing method provided in this embodiment is the same as that described in the previous embodiment, and will not be repeated here. The data sharing method provided in this embodiment is also used to implement the above system embodiment and optional implementation methods, and will not be repeated here.

[0255] In this embodiment, a data sharing method is provided. FIG5 is a flow chart of the data sharing method according to the embodiment of the present application. As shown in FIG5 , the process of the data sharing method includes:

[0256] Step 1: Get the available shared database image digest certificate from the blockchain.

[0257] This step corresponds to the aforementioned step of obtaining the image digest certificate available on the blockchain.

[0258] Step 2: Select the shared database mirror summary that meets the data element requirements.

[0259] This step corresponds to the aforementioned screening of the target image summary certificate from the image summary certificates available on the blockchain based on the data element requirement information.

[0260] Step 3: Obtain the DID document of the corresponding data sharing agent from the database mirror summary, and obtain the access interface for accessing the data sharing agent from the DID document.

[0261] Among them, the DID document of the data sharing agent is the digital identity document of the aforementioned first data sharing agent, and the access interface of the data sharing agent is the access interface of the aforementioned first data sharing agent.

[0262] Step 4: Initiate a data query request to the corresponding first data sharing agent.

[0263] Step 5: After receiving the query request, the first data sharing agent executes the query operation and obtains the query result.

[0264] Step 6: The first data sharing agent processes the query result according to the privacy protection policy corresponding to the database.

[0265] This step corresponds to the aforementioned first data sharing agent performing privacy protection processing on the target shared object based on the target privacy protection policy corresponding to the target shared object to obtain the shared object to be used.

[0266] Step 7: Return the processed results to the data user.

[0267] The data sharing method provided in this embodiment is the same as that described in the previous embodiment, and will not be repeated here. The data sharing method provided in this embodiment is also used to implement the above system embodiment and optional implementation methods, and will not be repeated here.

[0268] In this embodiment, a data sharing device is also provided, which is configured to implement the above-mentioned embodiments and optional implementation methods. The details already described will not be repeated here. As used below, the term "module" can mean a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.

[0269] This embodiment provides a data sharing device, which is applied to a data provider, and includes:

[0270] The key creation module is configured to use the first data sharing agent to create an asymmetric key, receive the object to be shared sent by the data provider, obtain the mirror summary declaration content of the object to be shared, and send the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror summary declaration content of the object to be shared to the target authentication service node, so that the target authentication service node generates the digital identity of the first data sharing agent, the digital identity document of the first data sharing agent, and the mirror summary certificate of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror summary declaration content of the object to be shared, and sends the digital identity of the first data sharing agent and the mirror summary certificate of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror summary certificate of the object to be shared in the blockchain.

[0271] Among them, the blockchain includes multiple blockchain nodes, which store the mirror summary certificate of the object to be shared by the data provider and the digital identity document of the first data sharing agent, so that the data user can access the target shared object in the first data sharing agent based on the mirror summary certificate of the object to be shared and the digital identity document of the first data sharing agent.

[0272] The functional descriptions of the above modules and units are the same as those in the above corresponding embodiments and will not be repeated here.

[0273] The data sharing device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0274] This embodiment provides a data sharing device, as shown in FIG6 , which is applied to a data user, including:

[0275] The target image summary certificate screening module 601 is configured to screen the target image summary certificate from the blockchain based on the data element requirement information.

[0276] The digital identity acquisition module 602 is configured to acquire the digital identity of the corresponding first data sharing agent from the target image digest credential.

[0277] The digital identity document acquisition module 603 is configured to acquire the digital identity document of the first data sharing agent from the blockchain based on the digital identity of the first data sharing agent.

[0278] The access interface information and public key acquisition module 604 is configured to acquire the access interface information and public key of the first data sharing agent from the digital identity document of the first data sharing agent. The first data sharing agent is configured to create an asymmetric key, receive an object to be shared from a data provider, acquire a mirror digest declaration of the object to be shared, and send the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration of the object to be shared to a target authentication service node, so that the target authentication service node generates a digital identity of the first data sharing agent, a digital identity document of the first data sharing agent, and a mirror digest credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration of the object to be shared. The target authentication service node then sends the digital identity of the first data sharing agent and the mirror digest credential of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared in a blockchain. The blockchain includes multiple blockchain nodes, and the blockchain nodes store the mirror digest credential of the object to be shared from the data provider and the digital identity document of the first data sharing agent.

[0279] The target shared object acquisition module 605 is configured to use the second data sharing agent to initiate a data query request to the first data sharing agent based on the target image summary certificate, the access interface information and the public key of the first data sharing agent, so that the first data sharing agent responds to the data query request, performs a data query operation, obtains the target shared object, and sends the target shared object to the data user.

[0280] The target shared object receiving module 606 is configured to receive a target shared object.

[0281] The functional descriptions of the above modules and units are the same as those in the above corresponding embodiments and will not be repeated here.

[0282] An embodiment of the present application also provides a computer device having any of the above-mentioned data sharing devices.

[0283] Please refer to Figure 7, which is a schematic diagram of the structure of a computer device provided in an optional embodiment of the present application. As shown in Figure 7, the computer device includes: one or more processors 701, a memory 702, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. The various components are connected to each other using different buses and can be installed on a common motherboard or installed in other ways as needed. The processor can process instructions executed within the computer device, including instructions stored in or on the memory to display graphical information of a GUI (Graphical User Interface) on an external input / output device (such as a display device coupled to the interface). In some optional embodiments, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 7 takes a processor 701 as an example.

[0284] Processor 701 may be a central processing unit, a network processor, or a combination thereof. Processor 701 may also include a hardware controller. The hardware controller may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.

[0285] The memory 702 stores instructions that can be executed by at least one processor 701, so as to enable the at least one processor 701 to execute the method shown in the above embodiment.

[0286] The memory 702 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 702 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 702 may optionally include a memory remotely located relative to the processor 701, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0287] The memory 702 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 702 may also include a combination of the above types of memory.

[0288] The computer device further includes a communication interface 703 for the computer device to communicate with other devices or a communication network.

[0289] The embodiments of the present application also provide a computer non-volatile readable storage medium. The above-mentioned method according to the embodiment of the present application can be implemented in hardware, firmware, or implemented as a computer code that can be recorded on a non-volatile readable storage medium, or implemented as a computer code that is originally stored in a remote non-volatile readable storage medium or a non-transitory machine non-volatile readable storage medium and is downloaded via a network and will be stored in a local non-volatile readable storage medium, so that the method described herein can be stored in such software processing on a non-volatile readable storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the non-volatile readable storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk, or a solid-state drive, etc.; the non-volatile readable storage medium can also include a combination of the above-mentioned types of memory. It can be understood that the computer, processor, microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by the computer, processor or hardware, the method shown in the above embodiment is implemented.

[0290] Part of the present application may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present application through the operation of the computer. Those skilled in the art should understand that the form in which the computer program instruction exists in a computer-readable medium includes but is not limited to a source file, an executable file, an installation package file, etc. Accordingly, the way in which the computer program instruction is executed by the computer includes but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium can be any available computer-readable non-volatile storage medium or communication medium that can be accessed by the computer.

[0291] Although the embodiments of the present application have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present application, and such modifications and variations shall fall within the scope defined by the appended claims.

Claims

1. A data sharing system, characterized in that: The system comprises: A first data sharing agent is configured to create an asymmetric key, receive an object to be shared from a data provider, obtain a mirror image summary declaration of the object to be shared, and send the public key in the asymmetric key, access interface information of the first data sharing agent, and the mirror image summary declaration of the object to be shared to a target authentication service node; The target authentication service node is configured to generate a digital identity of the first data sharing agent, a digital identity document of the first data sharing agent, and a mirror digest credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration content of the object to be shared, send the digital identity of the first data sharing agent and the mirror digest credential of the object to be shared to the first data sharing agent, and store the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared in the blockchain; The blockchain includes multiple blockchain nodes, which are used to store the mirror digest credential of the object to be shared by the data provider and the digital identity document of the first data sharing agent, so that the data user can access the target shared object in the first data sharing agent based on the mirror digest credential of the object to be shared and the digital identity document of the first data sharing agent.

2. The system according to claim 1, wherein: The system comprises: The data user is configured to filter the target image summary credential from the blockchain based on the data element requirement information, obtain the digital identity of the corresponding first data sharing agent from the target image summary credential, obtain the digital identity document of the first data sharing agent from the blockchain based on the digital identity of the first data sharing agent, obtain the access interface information and public key of the first data sharing agent from the digital identity document of the first data sharing agent, and send the target image summary credential, the access interface information and public key of the first data sharing agent to the second data sharing agent; a second data sharing agent, configured to initiate a data query request to the first data sharing agent based on the target image digest credential, the access interface information and the public key of the first data sharing agent; The first data sharing agent is further configured to respond to the data query request, perform a data query operation, obtain a target shared object, and send the target shared object to the second data sharing agent; The second data sharing agent is configured to receive the target shared object and send the target shared object to the data user.

3. The system according to claim 2, characterized in that The data user is used to: Obtain status information of the image summary credential on the blockchain, and filter a target image summary credential from the blockchain based on the status information of the image summary credential on the blockchain and the data element requirement information.

4. The system according to claim 2, wherein: The data user terminal is also used for: After receiving the target shared object, the data provider of the target shared object is incentivized through the incentive interface provided by the data sharing service smart contract pre-deployed on the blockchain.

5. The system according to claim 2, wherein: The first data sharing agent is connected to the blockchain node corresponding to the data provider, and the first data sharing agent is used to: Obtaining several privacy protection policies through the interface provided by the data privacy protection smart contract pre-deployed on the blockchain; If any of the privacy protection policies meets the preset privacy protection requirements, then the privacy protection policy is determined as the target privacy protection policy of the object to be shared; If none of the privacy protection policies meet the preset privacy protection requirements, then a new privacy protection policy that meets the preset privacy protection requirements is created on the blockchain through the interface provided by the data privacy protection smart contract pre-deployed on the blockchain, and the new privacy protection policy is used as the target privacy protection policy for the object to be shared; The first data sharing agent is configured to: In response to the data query request, executing a data query operation to obtain a target shared object, performing privacy protection processing on the target shared object based on a target privacy protection policy corresponding to the target shared object, obtaining a to-be-used shared object, and sending the to-be-used shared object to a second data sharing agent; The second data sharing agent is configured to: The shared object to be used is received, and the shared object to be used is sent to the data user.

6. The system according to claim 1, wherein: The first data sharing agent is further configured to: Put the object to be shared into the database mirror management queue, and put the mirror digest credential of the object to be shared into the mirror digest credential management queue; The first data sharing agent includes a database mirror management module and a mirror summary credential management module; The database mirror management module is configured to manage the database mirror management queue; The mirrored digest credential management module is configured to manage the mirrored digest credential management queue.

7. The system according to claim 1, wherein: The first data sharing agent is configured to: Obtain the loop time delay between the first data sharing agent and each service node in the distributed digital identity and verifiable credential service cluster, and use the service node with the shortest loop time delay with the first data sharing agent as the target authentication service node.

8. The system according to claim 1, wherein: The target authentication service node is used to: Generate a digital identity and a data identity document of the first data sharing agent based on the public key in the asymmetric key and the access interface information of the first data sharing agent; The first data sharing agent is further configured to: Receive the digital identity of the first data sharing agent, use the digital identity of the first data sharing agent to obtain an image summary credential template from the target authentication service node, fill in the image summary declaration content of the object to be shared according to the image summary credential template, obtain target image summary data, and send the target image summary data to the target authentication service node, so that the target authentication service node issues the image summary credential of the object to be shared based on the target image summary data.

9. The system according to claim 1, wherein: The target authentication service node is used to: The digital identity document of the first data sharing agent and the mirror summary certificate of the object to be shared are stored in the blockchain through the identity and certificate on-chain smart contract pre-deployed on the blockchain.

10. The system according to claim 1, wherein: The first data sharing agent is further configured to: In response to the update request of the object to be shared by the data provider, the received object to be shared is updated accordingly.

11. The system according to claim 1, wherein: The first data sharing agent is further configured to: In response to the mirror digest credential status modification request from the data provider, the status of the mirror digest credential in the mirror digest credential management queue is modified accordingly.

12. The system according to claim 1, wherein: The blockchain is also used to: In response to the mirror digest credential status modification request from the data provider, the stored mirror digest credential is modified accordingly.

13. The system according to claim 1, wherein: The first data sharing agent is further configured to: Receiving summary information of the object to be shared sent by the data provider; Based on the summary information of the object to be shared, the mirror summary declaration content of the object to be shared is determined.

14. A data sharing method, characterized in that: Applied to a data provider, the method includes: Using a first data sharing agent to create an asymmetric key, receiving an object to be shared sent by a data provider, obtaining a mirror digest declaration content of the object to be shared, and sending the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration content of the object to be shared to a target authentication service node, so that the target authentication service node generates a digital identity of the first data sharing agent, a digital identity document of the first data sharing agent, and a mirror digest credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration content of the object to be shared, and sends the digital identity of the first data sharing agent and the mirror digest credential of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared in a blockchain; In which, the blockchain includes multiple blockchain nodes, which store the mirror summary certificate of the object to be shared of the data provider and the digital identity document of the first data sharing agent, so that the data user can access the target shared object in the first data sharing agent based on the mirror summary certificate of the object to be shared and the digital identity document of the first data sharing agent.

15. A data sharing method, characterized in that: Applied to a data user, the method includes: Filter the target image summary certificate from the blockchain based on the data element requirement information; Obtaining a digital identity of a corresponding first data sharing agent from the target image digest credential; Obtaining a digital identity document of the first data sharing agent from the blockchain based on the digital identity of the first data sharing agent; Obtaining access interface information and a public key of the first data sharing agent from the digital identity document of the first data sharing agent; wherein the first data sharing agent is configured to create an asymmetric key, receive an object to be shared sent by a data provider, obtain a mirror digest declaration content of the object to be shared, and send the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration content of the object to be shared to a target authentication service node, so that the target authentication service node generates a digital identity of the first data sharing agent, a digital identity document of the first data sharing agent, and a mirror digest credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration content of the object to be shared, and sends the digital identity of the first data sharing agent and the mirror digest credential of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared in a blockchain, wherein the blockchain includes a plurality of blockchain nodes, and the blockchain nodes store the mirror digest credential of the object to be shared and the digital identity document of the first data sharing agent of the data provider; Initiate a data query request to the first data sharing agent using the second data sharing agent based on the target image digest credential, the access interface information and the public key of the first data sharing agent, so that the first data sharing agent responds to the data query request, performs a data query operation, obtains a target shared object, and sends the target shared object to the data user; The target shared object is received.

16. A data sharing device, characterized in that: Applied to a data provider, the device includes: a key creation module configured to create an asymmetric key using a first data sharing agent, receive an object to be shared from a data provider, obtain a mirror digest declaration content of the object to be shared, and send the public key in the asymmetric key, access interface information of the first data sharing agent, and the mirror digest declaration content of the object to be shared to a target authentication service node, so that the target authentication service node generates a digital identity of the first data sharing agent, a digital identity document of the first data sharing agent, and a mirror digest credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration content of the object to be shared, sends the digital identity of the first data sharing agent and the mirror digest credential of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared in a blockchain; In which, the blockchain includes multiple blockchain nodes, which store the mirror summary certificate of the object to be shared of the data provider and the digital identity document of the first data sharing agent, so that the data user can access the target shared object in the first data sharing agent based on the mirror summary certificate of the object to be shared and the digital identity document of the first data sharing agent.

17. A data sharing device, characterized in that: Applied to a data user, the device includes: a target image summary credential screening module, configured to screen the target image summary credential from the blockchain based on the data element requirement information; a digital identity acquisition module configured to acquire the digital identity of the corresponding first data sharing agent from the target image digest credential; a digital identity document acquisition module, configured to acquire the digital identity document of the first data sharing agent from the blockchain based on the digital identity of the first data sharing agent; An access interface information and public key acquisition module is configured to acquire the access interface information and public key of the first data sharing agent from the digital identity document of the first data sharing agent; wherein the first data sharing agent is used to create an asymmetric key, receive an object to be shared sent by a data provider, acquire a mirror digest declaration content of the object to be shared, and send the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration content of the object to be shared to a target authentication service node, so that the target authentication service node generates a digital identity of the first data sharing agent, a digital identity document of the first data sharing agent, and a mirror digest credential of the object to be shared based on the public key in the asymmetric key, the access interface information of the first data sharing agent, and the mirror digest declaration content of the object to be shared, and sends the digital identity of the first data sharing agent and the mirror digest credential of the object to be shared to the first data sharing agent, and stores the digital identity document of the first data sharing agent and the mirror digest credential of the object to be shared in a blockchain, wherein the blockchain includes multiple blockchain nodes, and the blockchain nodes store the mirror digest credential of the object to be shared and the digital identity document of the first data sharing agent. a target shared object acquisition module configured to use the second data sharing agent to initiate a data query request to the first data sharing agent based on the target image digest credential, the access interface information and the public key of the first data sharing agent, so that the first data sharing agent responds to the data query request, performs a data query operation, obtains the target shared object, and sends the target shared object to the data user; The target shared object receiving module is configured to receive the target shared object.

18. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the data sharing method according to claim 14 or the data sharing method according to claim 15 by executing the computer instructions.

19. A computer-readable non-volatile storage medium, characterized in that: The computer non-volatile readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the data sharing method according to claim 14 or the data sharing method according to claim 15.

20. A computer program product, characterized in that The method comprises computer instructions for causing a computer to execute the data sharing method according to claim 14 or the data sharing method according to claim 15.

Citation Information

Patent Citations

  • Data hosting method and system based on blockchain and distributed identity

    CN111884805A

  • Data right confirmation method and system based on block chain technology

    CN112651052A

  • Medical data sharing method, device and equipment and computer readable medium

    CN112908442A

  • Method for sharing user-specific data of user, computer program and data sharing system

    CN114762291A

  • Trusted authorization data sharing method based on distributed identity and alliance chain

    CN117200966A

Cited By

  • Organic tea traceability authentication method and system based on block chain

    CN121526647A